Real-time threat detection
Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process.
July 2026 — the entire x2y suite is now free. Code Leak Detector moves to a one-time $29 on 1 Sep.
View productsWindows Security Software
Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures, persistence auditing, and network monitoring. Protects your system without slowing it down.
Free — no account, no subscription, no telemetry. Donationware since July 2026.

Key features
Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process.
Offline signature bundles sourced from MalwareBazaar (recent and full feeds), URLhaus malicious URL detection, OpenPhish phishing protection, and the ClamAV freshclam database. Updated manually — the app never phones home.
Deep analysis of startup entries, registry run keys, scheduled tasks, services and browser extensions. Identifies persistence mechanisms used by malware to survive reboots — before they activate.
Real-time process mapping and traffic flow visualisation. See every active connection — protocol, remote address, PID, process name, state and risk level — at a glance. Export to CSV for forensic analysis.
Suspicious files are isolated in an encrypted local vault — not deleted, not uploaded. Review, restore or permanently remove at your discretion. Full audit trail of every quarantine action.
Compute and verify file hashes locally against known-good baselines. Integrity monitoring across 1,024+ watchpaths alerts on unexpected modification of binaries, configs and boot paths.
Threat sources
RECENT + FULL FEEDS
MALICIOUS URL DETECTION
PHISHING PROTECTION
FRESHCLAM DATABASE
Specifications
| Product | x2y AV Ultimate |
|---|---|
| Version | v8.5.0 |
| Platform | Windows 10, Windows 11 |
| Architecture | x64 (64-bit) |
| Signatures | 5,500+ (offline bundle) |
| Engines | ClamAV 0.105, YARA 4.5 |
| Threat intel | MalwareBazaar, URLhaus, OpenPhish, ClamAV freshclam |
| Watchpaths | 1,024+ integrity monitor paths |
| Network monitor | Real-time TCP/UDP with process mapping |
| Quarantine | Encrypted local vault, restorable |
| Hash algorithms | SHA-256, MD5 |
| Export | CSV (network connections, scan reports) |
| Telemetry | 0 bytes — verified continuously |
| Account required | None — ever |
| Price | Free — donationware since Jul 2026 |
| Developer | x2y Devs Tools Ltd, Nairobi, Kenya |
Quick start
Get the installer from Microsoft Store, itch.io or GitHub. Verify the SHA-256 checksum against the published value.
Run the signed installer. No administrator privileges required for standard installs. No account creation, no activation key.
Signature bundles load from disk automatically. ClamAV and YARA initialise with 5,500+ offline signatures. The integrity monitor arms 1,024+ watchpaths.
Run a full scan, enable real-time protection, or open the Network Monitor. Every verdict is reached locally. Telemetry sent: 0 B.
Downloads
Changelog
Threat intelligence refresh to 5,500+ signatures. New persistence auditor module. Network activity monitor with real-time process mapping and traffic flow graph. Hardened installer with published SHA-256 checksums.
New dual-engine detection pipeline (ClamAV + YARA). Integrity monitor with configurable watchpaths. Quarantine vault with encrypted local storage.
Initial public launch. Core scanning engine, basic threat detection, Windows 10/11 support.
Security model
Every claim above is independently verifiable. Run Wireshark, Fiddler, GlassWire, or your operating system's firewall logs while using x2y AV Ultimate. You will observe zero outbound connections attributable to the application. We encourage this verification.
| Telemetry | 0 bytes collected |
|---|---|
| Account | None required — ever |
| Data egress | None by design |
| Engines | ClamAV 0.105 · YARA 4.5 |
| Threat feeds | Offline bundles only |
| Quarantine | Encrypted local vault |
| Installer | Signed · SHA-256 published |
| Verification | Any network monitor |
Ready to protect your system
No account. No subscription. No telemetry. Just comprehensive Windows security that works when the network is off.
| Version | v8.5.0 |
|---|---|
| Platform | Windows 10 / 11 |
| Price | Free — donationware |
| Telemetry | 0 bytes |